// MITRE ATT&CK

T1070.007 · Clear Network Connection History and Configurations

🎯 Stealth LinuxmacOSWindowsNetwork Devices Sub-technique

Sub-technique of T1070 · Indicator Removal.

Adversaries may clear or remove evidence of malicious network connections in order to clean up traces of their operations. Configuration settings as well as various artifacts that highlight connection history may be created on a system and/or in application logs from behaviors that require network c...

How to detect & mitigate it

Detecting Clear Network Connection History and Configurations starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.